Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Debian 11 bullseye: DLA-4132-1 critical: erlang remote code execution

debian lts
Calendar Grey April 20, 2025
Dist Debian Esm H88
A vital Erlang patch tackles various vulnerabilities in Debian LTS, notably the Terrapin exploit and risks of possible RCE.
Multiple vulnerabilties were fixed in erlang

Summary

CVE-2023-48795 (Terrapin attack)

The SSH transport protocol with certain OpenSSH extensions,
allows remote attackers to bypass integrity checks such
that some packets are omitted (from the extension
negotiation message), and a client and server may
consequently end up with a connection for which
some security features have been downgraded.

CVE-2025-26618

The SSH transport protocol with certain OpenSSH extensions,
allows remote attackers to bypass integrity checks such
that some packets are omitted (from the extension
negotiation message), and a client and server may
consequently end up with a connection for which
some security features have been downgraded.

CVE-2025-30211

The SSH transport protocol with certain OpenSSH extensions,
allows remote attackers to bypass integrity checks such
that some packets are omitted (from the extension
negotiation message), and a client and server may
consequently end up with a connection for which

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: erlang
Version: 1:23.2.6+dfsg-1+deb11u2
CVE ID: CVE-2023-48795 CVE-2025-26618 CVE-2025-30211 CVE-2025-32433
Debian Bug: 1059002 1101713 1103442

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here